AI Laws by State — Complete 2026 Guide
The US does not have a single federal AI law yet. Instead, each state is moving independently. This guide covers every state — which ones have laws in force, which have laws coming, and which have no AI-specific regulation at all.
What about federal AI law?
The US has no comprehensive federal AI law as of April 2026. Congress has introduced bills but none have passed. Existing federal laws (FTC Act, ADA, Title VII, FCRA, HIPAA, COPPA) all apply to AI use in their respective domains — but there is no AI-specific federal statute. States are filling the gap.
States with AI laws in effect now
Law
Colorado ADMT Law (SB 26-189)
Deadline / Effective
1 Jan 2027
Key Requirements
ADMT pre-use notice, 30-day post-adverse-outcome disclosure, data correction + human review on request, 3-year recordkeeping for employment/credit/healthcare/housing decisions. No impact assessment (that was the repealed SB 24-205).
Maximum Fine
Up to $20,000 per violation ($50,000 if elderly victim); AG-only, no private right of action
Law
CPRA ADMT + AB 2013 + SB 942
Deadline / Effective
Various: Jan 2026 (AB 2013), Aug 2026 (SB 942)
Key Requirements
AI training data transparency (AB 2013); AI content labeling (SB 942); automated decision-making opt-out (CPRA)
Maximum Fine
Up to $7,500 per intentional violation (CPRA)
Law
Texas TRAIGA (HB 149)
Deadline / Effective
January 1, 2026 (in effect)
Key Requirements
Intent-based prohibitions (not risk-tier obligations): bars intentional discrimination, manipulation causing self-harm/violence, non-consensual sexual content, and government social scoring; government AI-interaction disclosure. No impact assessment or risk-management-program requirement.
Maximum Fine
Up to $200,000 per uncurable violation, plus $40,000/day for continuing violations — AG-only, no private right of action
Law
AIVIA + HB 3773 (Human Rights Act AI amendment) + BIPA
Deadline / Effective
AIVIA in force 2020; HB 3773 signed Aug 2024, effective Jan 1, 2026 (in force); BIPA 2008
Key Requirements
AIVIA: notify candidates before video-AI analysis, obtain consent, 30-day deletion on request. HB 3773: bars AI with discriminatory effect on a protected class, bars ZIP-code proxy use, requires AI-use notice — across the whole employment lifecycle, not just video interviews. BIPA: biometric data consent.
Maximum Fine
Up to $5,000 per intentional/reckless violation ($1,000 if negligent) — one violation per person, per identifier, not per day; private right of action
Law
Utah AI Policy Act (SB 149, as amended by 2025 SB 226/332, HB 452, SB 271; sunsets July 1, 2027)
Deadline / Effective
In effect May 2024
Key Requirements
Disclose AI interaction to users in high-risk interactions, liability for AI-generated professional advice; HB 452 bars mental-health chatbots from selling user health data to third parties
Maximum Fine
Utah Division of Consumer Protection enforcement — up to $2,500/violation ($5,000 for violating an administrative or court order)
Law
ELVIS Act + Healthcare AI Act (SB 1580)
Deadline / Effective
ELVIS: July 2024; SB 1580: July 1, 2026
Key Requirements
ELVIS: AI voice/likeness rights. SB 1580: bars AI systems/vendors from advertising or representing themselves as a qualified mental health professional (does not restrict clinician-supervised use of AI as a tool).
Maximum Fine
ELVIS: up to $10,000/violation. SB 1580: TCPA unfair/deceptive-practice penalty up to $5,000/violation, plus a private right of action.
Law
Maryland Healthcare AI Act (HB 820)
Deadline / Effective
October 1, 2025 (in effect)
Key Requirements
Health insurance carriers/PBMs/private review agents cannot use AI to deny, delay, or modify care in utilization review without individualized clinical review by a qualified licensed reviewer
Maximum Fine
Misdemeanor charges, monetary penalties, cease-and-desist orders, and administrative license actions (denial/suspension/revocation)
Law
NYC Local Law 144
Deadline / Effective
July 2023 (in effect)
Key Requirements
Annual third-party bias audit for automated employment decision tools; public posting of results
Maximum Fine
Up to $500-$1,500/day per violation
Law
Nevada AB 406 (Mental Health AI)
Deadline / Effective
July 1, 2025 (in effect)
Key Requirements
Bars companies from offering/claiming an AI system can provide professional mental or behavioral healthcare; bars public schools from using AI in place of counselors/psychologists/social workers; licensed providers limited to administrative AI use
Maximum Fine
Up to $15,000 per violation, plus professional license discipline (suspension/revocation) for licensed providers
Law
HB 143 (AI chatbot child safety)
Deadline / Effective
Signed Aug 1, 2025 — effective January 1, 2026 (in effect)
Key Requirements
Bars AI chatbot/online-service operators from using AI to facilitate, encourage, offer, solicit, or recommend harmful acts to children (sexual conduct, drugs/alcohol, self-harm, violence)
Maximum Fine
Private right of action, $1,000/violation minimum, plus AG enforcement (90-day cure period before AG-initiated liability attaches)
Law
Digital Forgery Act (SB 649 / Act 35 of 2025)
Deadline / Effective
Signed July 7, 2025 — effective September 5, 2025 (in effect)
Key Requirements
Bars non-consensual AI-forged digital likenesses/voice clones used to defraud or harm (e.g. voice-clone scams); satire/parody/commentary/law-enforcement exceptions apply
Maximum Fine
First-degree misdemeanor generally; third-degree felony if used with fraudulent intent
Law
CTDPA AI amendment (PA 25-113) + CART Act (PA 26-15)
Deadline / Effective
PA 25-113: in force since July 1, 2026. CART Act: most provisions Oct 1, 2026; AI companions Jan 1, 2027; employment adverse-decision notices Oct 1, 2027.
Key Requirements
PA 25-113: clear privacy-notice disclosure of AI/LLM-training data use. CART Act: pre-contract disclosures for subscription AI, employment-decision-tool transparency (purpose, data used) before adverse decisions, AI-companion self-harm detection and under-18 safeguards, watermarking for high-reach generative content, whistleblower protections for frontier-model staff.
Maximum Fine
CT AG (CUTPA) enforcement; CART Act frontier-developer penalties up to $1,000/violation; private right of action only for AI-companion violations involving minors
Law
AI Election Media Act (S.23 / Act 75)
Deadline / Effective
Signed March 2026 (in effect)
Key Requirements
Deceptive AI-generated images/audio/video in campaign media released within 90 days of an election must carry a visible manipulation disclosure
Maximum Fine
Up to $1,000 (basic violation), $5,000 (intent to cause violence/harm), $10,000 (repeat offense), $15,000 (repeat + intent to harm); additional $5,000 for obstructing an investigation
Law
SB 41 (Deepfake pornography felony)
Deadline / Effective
Signed March 17, 2026 — effective July 1, 2026 (in effect)
Key Requirements
Creating/distributing AI-generated intimate images of a non-consenting adult is a felony
Maximum Fine
Felony, up to 2 years imprisonment
Law
Montana Right to Compute Act (SB 212)
Deadline / Effective
April 17, 2025 (in effect)
Key Requirements
Establishes a right to own/use computing resources (incl. AI) that government may restrict only under strict scrutiny; AI-controlled critical infrastructure must have a human-override shutdown mechanism and an annual risk-management review
Maximum Fine
No published agency fine schedule found — enforceable via litigation under the strict-scrutiny standard
Law
Synthetic Media Laws (HF2499 election deepfakes + HF526 nonconsensual intimate images)
Deadline / Effective
July 1, 2024 (in effect)
Key Requirements
Bans deceptive/fraudulent election-related deepfakes made with intent to influence an election or cause harm (a clear manipulation disclosure is a defense); separately bans nonconsensual intimate-image deepfakes
Maximum Fine
Election deepfakes: simple/serious misdemeanor up to $2,560, or Class D felony (up to 5 years, up to $10,245) for a repeat violation within 5 years
Law
A3540 (Deepfakes Law / P.L.2025, c.40)
Deadline / Effective
Signed April 2, 2025 (in effect)
Key Requirements
Bans producing/distributing deepfakes for an unlawful purpose — sexual exploitation, false/misleading political ads, harassment, or extortion; exemptions for satire, parody, news reporting, teaching, and research
Maximum Fine
Third-degree crime — up to $30,000 and/or up to 5 years imprisonment; separate civil penalties also available
Law
HB 2175 (AI in health insurance denials)
Deadline / Effective
Signed May 12, 2025; effective July 1, 2026 (in force)
Key Requirements
A licensed medical director/provider must individually review any medical-necessity or prior-authorization denial — AI cannot be the sole or final decision-maker in denying a health insurance claim. (Note: a separate 2026 chatbot child-safety bill, HB 2311, was vetoed June 19, 2026 and is not law.)
Maximum Fine
Enforced via AZ Department of Insurance and Financial Institutions; no published flat per-violation figure found
Law
HF 1606 (Nudification Technology Ban)
Deadline / Effective
Signed May 2026 — effective August 1, 2026 (in effect)
Key Requirements
Bars accessing, downloading, or using AI "nudification" technology to digitally strip clothing from real people’s images/videos without consent
Maximum Fine
Private right of action (up to 3x actual damages, punitive damages, attorney fees) plus AG civil penalties up to $500,000/violation
Law
AI Sexual-Exploitation-Images Law (2025 package)
Deadline / Effective
Signed August 2025 (in effect)
Key Requirements
Criminalizes creating/distributing AI-generated sexually explicit images or videos of a real, identifiable person without consent
Maximum Fine
Criminal (felony) penalties — specific per-violation dollar figure not independently confirmed this cycle
Law
2023 Wisconsin Act 123 (Political AI Disclosure)
Deadline / Effective
In effect since March 2024
Key Requirements
Political ads containing AI/synthetic media must carry a clear disclosure statement; Wisconsin Ethics Commission has rulemaking authority
Maximum Fine
Enforced via Wisconsin Ethics Commission — specific per-violation dollar figure not independently confirmed this cycle
Law
Session Law 2024-37 (HB 591, AI Deepfake Intimate Images)
Deadline / Effective
In effect since 2024
Key Requirements
Expands criminal penalties to cover AI-generated nonconsensual intimate deepfake images
Maximum Fine
Criminal penalties — specific figure not independently confirmed this cycle
Law
HB 119 (AI-Generated CSAM) + HB 459 (Political AI Ad Disclosure)
Deadline / Effective
Both effective August 1, 2026 (in effect)
Key Requirements
HB 119: criminalizes AI-generated sexual imagery of minors. HB 459: political ads with materially AI-altered images/audio/video must disclose AI use.
Maximum Fine
HB 119: 5-20 years imprisonment at hard labor, up to $10,000. HB 459: up to $10,000 and/or up to 2 years imprisonment.
Law
HB 172 (Materially Deceptive Media) + Child Protection Act (2024)
Deadline / Effective
HB 172 signed 2026; Child Protection Act in effect since 2024
Key Requirements
Criminal sanctions for deceptive AI deepfakes; AI-generated child sexual abuse material covered under the Child Protection Act; the private-image statute also covers AI-generated intimate deepfakes of adults
Maximum Fine
Criminal penalties — specific figures not independently confirmed this cycle
Law
Act 827/HB 1529 (Deepfake Sexual Material) + HB 1071 (AI Voice/Likeness Consent) + HB 1877 (AI CSAM)
Deadline / Effective
Act 827 signed April 18, 2025 (in effect)
Key Requirements
Criminalizes nonconsensual sexual deepfakes; requires consent for commercial AI voice/likeness replication; expands criminal liability for AI-generated CSAM
Maximum Fine
Criminal penalties — specific figures not independently confirmed this cycle
Law
HB 2137 (AI Deepfake Civil Liability) + SB 3001 (AI Disclosure and Safety Act)
Deadline / Effective
Signed July 14, 2026 (in effect)
Key Requirements
Civil right of action against harmful AI-generated deepfakes; AI companion/chatbot operators must disclose their AI nature and provide self-harm response protocols
Maximum Fine
HB 2137: up to $25,000 per piece of content (civil damages)
Law
HEA 1133 (Political Deepfake Disclaimer) + HB 1047 (2026, Minors Synthetic Media)
Deadline / Effective
HEA 1133 in effect; HB 1047 enacted 2026
Key Requirements
Political ads using AI-generated/digitally altered media require a disclaimer (civil action available if omitted); separate criminal provisions cover AI-generated synthetic media involving minors
Maximum Fine
Civil action (HEA 1133); criminal penalties (HB 1047) — specific figures not independently confirmed this cycle
Law
SB 186 (AI-Generated CSAM) + HB 2183 (Deepfake Provisions)
Deadline / Effective
In effect 2026
Key Requirements
Criminalizes possession, creation, and distribution of AI-generated child sexual abuse material; person-felony penalties for deepfake offenses
Maximum Fine
Felony penalties — specific figures not independently confirmed this cycle
Law
SB 4 (Election Synthetic Media) + HB 63 (Deepfake Dissemination Liability)
Deadline / Effective
In effect 2026
Key Requirements
Political synthetic media requires adequate disclosure or invites civil action; knowingly sharing a deepfake of a person without consent creates civil liability for damages, costs, and attorney fees
Maximum Fine
Civil liability — specific statutory cap not independently confirmed this cycle
Law
LD 517 (Political Deepfake Disclosure) + LD 2082 (AI Therapy Ban) + LD 1944 (Synthetic Intimate Imagery)
Deadline / Effective
LD 517 signed March 23, 2026; LD 2082 signed April 13, 2026 (in effect)
Key Requirements
Political ads with AI-altered content require a specific manipulation-disclosure statement; bars unlicensed persons or AI from offering therapy/psychotherapy services; criminal penalties for nonconsensual synthetic intimate imagery
Maximum Fine
Criminal/civil penalties — specific figures not independently confirmed this cycle
Law
SB 2050 (Political AI Ad Disclosure) + Mississippi ELVIS Act (2025) + AI-CSAM statute
Deadline / Effective
In effect 2025-2026
Key Requirements
Political ads using AI must disclose its use; establishes property rights over likeness/voice/image (descendible 10 years post-death); AI-generated child sexual imagery is classified as child exploitation
Maximum Fine
Penalties for unauthorized likeness use — specific figures not independently confirmed this cycle
Law
LB 525 (Conversational Artificial Intelligence Safety Act)
Deadline / Effective
Signed April 14, 2026 (in effect)
Key Requirements
AI chatbot operators must disclose their AI nature to all users, apply extra safeguards for minors, and may not claim to provide professional mental/behavioral healthcare
Maximum Fine
Specific per-violation dollar figure not independently confirmed this cycle
Law
HB 1167 (Political Synthetic Media Disclosure) + HB 1386 (Minors) + HB 1351 (Nonconsensual Intimate Imagery)
Deadline / Effective
In effect 2026
Key Requirements
Political synthetic content requires disclosure; separate criminal provisions cover AI-generated content involving minors and nonconsensual intimate imagery
Maximum Fine
Criminal penalties — specific figures not independently confirmed this cycle
Law
S 2195 (AI Companion Safety) + H 7538 (Healthcare AI Documentation Disclosure) + 2025 deepfake laws
Deadline / Effective
Signed June 22, 2026 (in effect)
Key Requirements
AI companion platforms must provide self-harm crisis protocols and routinely remind users they are not human; healthcare providers using AI for visit documentation must notify patients; separate July 2025 laws criminalize AI intimate-image deepfakes and require election synthetic-media disclosure
Maximum Fine
Up to $15,000/day for AI-companion self-harm-routing failures
Law
H 3058 and companion AI-criminal-provision bills (signed May 2025)
Deadline / Effective
Signed May 12, 2025 (in effect)
Key Requirements
Criminalizes intentional distribution of intimate images or digitally forged intimate content. (A separate election-deepfake disclosure bill, H 3517, remains only introduced — not enacted.)
Maximum Fine
Criminal penalties — specific figures not independently confirmed this cycle
Law
HB 102 (Protecting Kids from Deepfakes and Exploitative Images)
Deadline / Effective
Effective July 1, 2026 (in effect)
Key Requirements
Felony offenses for nonconsensual synthetic sexual material, AI systems built for CSAM, or AI systems intended to promote self-harm
Maximum Fine
Felony — up to 10 years imprisonment and a $10,000 fine
Law
HB 919 (Political AI Disclaimer) + Brooke’s Law (AI Deepfake Platform Takedown)
Deadline / Effective
HB 919 in effect since July 1, 2024; Brooke’s Law signed 2025 (in effect)
Key Requirements
Political ads with AI-generated content depicting a real person in a false light require a disclaimer; social media platforms must remove nonconsensual AI-generated sexual depictions within 48 hours of a verified request. (A broader 2026 "AI Bill of Rights," SB 482, died in the House March 13, 2026 — not enacted.)
Maximum Fine
Civil action (HB 919); platform compliance duty (Brooke’s Law) — specific per-violation figures not independently confirmed this cycle
States with AI laws coming soon
Law
HB 1170 (AI content disclosure/watermarking)
Expected Effective Date
Signed March 24, 2026 — effective January 1, 2028
Key Requirements
Platforms with 1M+ WA monthly users must disclose AI-developed/modified content, offer a free AI-detection tool, and embed traceable watermarks/metadata. (Political-ad-specific AI disclosure is a separate, already-in-force 2023 election deepfake law, not HB 1170.)
Law
SB 1546 (AI Companion Chatbot Act)
Expected Effective Date
Signed April 1, 2026 — effective January 1, 2027
Key Requirements
AI companion chatbots must regularly remind users they are AI (not human), may not deceptively simulate a human relationship, must detect suicidal ideation and connect users to crisis resources (e.g. 988), with extra protections for minors
Law
Conversational AI Safety Act (S1297)
Expected Effective Date
Signed March 31, 2026 — effective July 1, 2027
Key Requirements
Conversational AI operators must clearly disclose AI nature to users, implement suicide/self-harm detection with 988 crisis-line referrals, and apply extra protections for minors (including a ban on deceptive personification); no private right of action
Law
SB 540 (AI chatbot disclosure)
Expected Effective Date
Signed by Gov. Kemp May 11, 2026 — effective July 1, 2027
Key Requirements
Proactive in-conversation AI-identity disclosure (start of chat + every 3 hours; every 1 hour for minors); child self-harm/suicide intervention mechanism; no big-tech exemption
Law
RAISE Act (Responsible AI Safety and Education Act)
Expected Effective Date
Signed Dec 19, 2025; finalized March 27, 2026 — effective January 1, 2027
Key Requirements
Frontier AI model developers above a compute/spend threshold must publish safety protocols, report safety incidents within 72 hours, and undergo third-party audits, overseen by a new NY Dept. of Financial Services AI office. (Separate from NYC Local Law 144, which applies today to hiring tools citywide.)
States with no AI-specific law (yet)
These states have no AI-specific legislation signed into law as of August 2026. However, federal law still applies: FTC Act (deceptive practices), Title VII and ADA (employment discrimination by AI), FCRA (AI in credit decisions), COPPA (AI and children under 13), and HIPAA (AI and medical data).
What does this mean for your business?
If you are in a no-law state
Federal law applies. Your biggest risks: using AI in hiring (Title VII), credit (FCRA), or healthcare (HIPAA). You also need to comply with the laws of any state where your customers live — if you have customers in Colorado or Texas, their state AI laws may apply to you.
If you operate in multiple states
You need to comply with the strictest law that applies to your situation. If you have customers in Colorado, the Colorado AI Act applies to how you use AI with those customers — even if your business is based in a no-law state.
If you use AI for hiring, credit, or health decisions
Illinois AIVIA, NYC Local Law 144, Colorado AI Act, Texas TRAIGA, and Maryland Healthcare AI Act all specifically target these use cases. Compliance is mandatory, not optional.
The trend is clear
2026 is the year of state AI law. The Future of Privacy Forum's chatbot-legislation tracker counts nearly 100 chatbot-specific bills across more than 30 states in 2026, with a dozen already signed into law. Even if your state has no law today, it may within 12 months. Building compliant AI practices now is significantly cheaper than retrofitting them later.
Legal disclaimer: This guide is for informational purposes only. Laws change frequently. Consult a qualified legal professional for advice specific to your business. Verify current law text at official state sources before relying on this guide.
Find out which laws apply to your business
Aegis Firma covers all 169 jurisdictions — US states, EU, Canada, APAC, and more. Answer 4 questions and get a personalized list of laws that apply to your business, with deadlines and required actions.